CVE Tools
Back to feed
Incident Oracle E-Business Suite Clop data-breach Oracle malware

Estée Lauder discloses data breach via Oracle E-Business flaw

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Cosmetics giant Estée Lauder has disclosed a data breach following an attack that exploited a vulnerability in Oracle E-Business Suite (CVE-2025-61882). Hackers gained unauthorized access on August 9, 2025, stealing personal details such as full names, Social Security numbers, health records, and financial account information. The flaw allowed remote code execution and was actively exploited by the Clop ransomware group since early 2025. Oracle issued patches for the issue in October 2025, but the breach highlights ongoing risks for organizations using unpatched systems.